test_cgrp2_tc.bpf.c 1.5 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556
  1. /* Copyright (c) 2016 Facebook
  2. *
  3. * This program is free software; you can redistribute it and/or
  4. * modify it under the terms of version 2 of the GNU General Public
  5. * License as published by the Free Software Foundation.
  6. */
  7. #define KBUILD_MODNAME "foo"
  8. #include "vmlinux.h"
  9. #include "net_shared.h"
  10. #include <bpf/bpf_helpers.h>
  11. /* copy of 'struct ethhdr' without __packed */
  12. struct eth_hdr {
  13. unsigned char h_dest[ETH_ALEN];
  14. unsigned char h_source[ETH_ALEN];
  15. unsigned short h_proto;
  16. };
  17. struct {
  18. __uint(type, BPF_MAP_TYPE_CGROUP_ARRAY);
  19. __type(key, u32);
  20. __type(value, u32);
  21. __uint(pinning, LIBBPF_PIN_BY_NAME);
  22. __uint(max_entries, 1);
  23. } test_cgrp2_array_pin SEC(".maps");
  24. SEC("filter")
  25. int handle_egress(struct __sk_buff *skb)
  26. {
  27. void *data = (void *)(long)skb->data;
  28. struct eth_hdr *eth = data;
  29. struct ipv6hdr *ip6h = data + sizeof(*eth);
  30. void *data_end = (void *)(long)skb->data_end;
  31. char dont_care_msg[] = "dont care %04x %d\n";
  32. char pass_msg[] = "pass\n";
  33. char reject_msg[] = "reject\n";
  34. /* single length check */
  35. if (data + sizeof(*eth) + sizeof(*ip6h) > data_end)
  36. return TC_ACT_OK;
  37. if (eth->h_proto != bpf_htons(ETH_P_IPV6) ||
  38. ip6h->nexthdr != IPPROTO_ICMPV6) {
  39. bpf_trace_printk(dont_care_msg, sizeof(dont_care_msg),
  40. eth->h_proto, ip6h->nexthdr);
  41. return TC_ACT_OK;
  42. } else if (bpf_skb_under_cgroup(skb, &test_cgrp2_array_pin, 0) != 1) {
  43. bpf_trace_printk(pass_msg, sizeof(pass_msg));
  44. return TC_ACT_OK;
  45. } else {
  46. bpf_trace_printk(reject_msg, sizeof(reject_msg));
  47. return TC_ACT_SHOT;
  48. }
  49. }
  50. char _license[] SEC("license") = "GPL";